베어메탈 UPI(user-provisioned infrastructure) 설치의 요구사항이다. 머신 · DNS · 로드밸런서 · 방화벽을 installer 가 만들어 주지 않으므로 전부 미리 준비해야 한다. OCP 4.x 문서 모듈을 기준으로 정리했다[1].
| 머신 | 수 | OS |
|---|---|---|
| Bootstrap | 1 (설치 뒤 제거) | RHCOS |
| Control plane | 3 | RHCOS |
| Compute | 2 이상 | RHCOS 또는 RHEL 8.6 이상 |
베어메탈에서는 control plane 3 대만으로 compute 없이 시험 · 개발용 클러스터를 만들 수 있다 (control plane 이 워크로드까지 받는다).
| 머신 | vCPU | RAM | 디스크 | IOPS |
|---|---|---|---|---|
| Bootstrap | 4 | 16 GB | 100 GB | 300 |
| Control plane | 4 | 16 GB | 100 GB | 300 |
| Compute | 2 | 8 GB | 100 GB | 300 |
etcd 가 control plane 디스크 지연에 민감하므로 300 IOPS 는 최소치다. SSD 를 쓴다.
<cluster_name>.<base_domain> 아래에 다음 레코드가 필요하다. PTR 까지 있어야 RHCOS 가 자기 호스트 이름을 알아낸다.
| 구성 요소 | 레코드 | PTR | 설명 |
|---|---|---|---|
| Kubernetes API | api.<cluster_name>.<base_domain>. |
필요 | API 로드밸런서. 외부 · 내부 모두에서 풀려야 한다 |
| Kubernetes API | api-int.<cluster_name>.<base_domain>. |
필요 | 내부용 API 로드밸런서. 클러스터 노드에서만 풀리면 된다 |
| Routes | *.apps.<cluster_name>.<base_domain>. |
불필요 | 인그레스 로드밸런서를 가리키는 와일드카드 |
| Bootstrap | bootstrap.<cluster_name>.<base_domain>. |
필요 | 부트스트랩 머신 |
| Control plane | <control_plane><n>.<cluster_name>.<base_domain>. |
필요 | 머신마다 하나 |
| Compute | <compute><n>.<cluster_name>.<base_domain>. |
필요 | 머신마다 하나 |
4.4 부터 etcd 호스트 · SRV 레코드는 필요 없다.
L4 로드밸런서 둘이 필요하다. HAProxy 하나에 두 역할을 다 두어도 된다.
| 대상 | 포트 | 백엔드 |
|---|---|---|
| API | 6443/tcp | bootstrap + control plane (부트스트랩 뒤 bootstrap 제거) |
| Machine Config Server | 22623/tcp | bootstrap + control plane |
| Ingress HTTP | 80/tcp | Ingress Controller 가 도는 노드 (기본은 compute) |
| Ingress HTTPS | 443/tcp | 같음 |
| 프로토콜 | 포트 | 용도 |
|---|---|---|
| ICMP | — | 네트워크 도달성 |
| TCP | 1936 | 메트릭 |
| TCP | 9000-9999 | 호스트 서비스. node exporter 9100-9101, Cluster Version Operator 9099 |
| TCP | 10250-10259 | Kubernetes 예약 포트 |
| TCP | 22623 | Machine Config Server → control plane |
| UDP | 6081 | Geneve (OVN-Kubernetes) |
| UDP | 9000-9999 | 호스트 서비스 |
| UDP | 500 · 4500 | IPsec IKE · NAT-T (IPsec 을 켤 때) |
| UDP | 123 | NTP |
| TCP/UDP | 30000-32767 | NodePort |
| ESP | — | IPsec ESP |
| 프로토콜 | 포트 | 용도 |
|---|---|---|
| TCP | 6443 | Kubernetes API |
| 프로토콜 | 포트 | 용도 |
|---|---|---|
| TCP | 2379-2380 | etcd 서버 · 피어 |
chrony MachineConfig 로 지정한다.ip=...) 나 coreos-installer --copy-network 로 넣는다.core 사용자로 노드에 들어갈 공개키.installer · oc 다운로드는 OpenShift Install preparation 에 있다.
2026-09-20 확인. https://github.com/openshift/openshift-docs/blob/main/modules/installation-minimum-resource-requirements.adoc · installation-dns-user-infra.adoc · installation-network-user-infra.adoc · installation-machine-requirements.adoc ↩︎